ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A company is implementing a new security policy that requires all remote employees to use a VPN and then provide a password and a one-time code from a mobile authenticator app to access internal network resources. Which access control concept is being strengthened by combining these authentication methods?

  1. AAuthorization
  2. BSingle Sign-On (SSO)
  3. CMulti-Factor Authentication (MFA)
  4. DIdentification
Show answer & explanation

Correct answer: C. Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to provide two or more distinct types of authentication factors (e.g., something you know like a password, and something you have like a mobile authenticator app) to verify their identity, significantly enhancing security.

Why the other options are wrong

  • A. Authorization grants permissions after authentication, it's not the authentication method itself.
  • B. SSO aims for convenience by reducing logins, not necessarily strengthening authentication factors directly.
  • D. Identification is claiming an identity, not proving it with multiple factors.

Multi-Factor Authentication (MFA)

An authentication method that requires a user to present two or more distinct authentication factors from different categories (e.g., knowledge, possession, inherence) to verify their identity.

  • Significantly improves security against credential theft.
  • Common factors: password (knowledge), token/app (possession), fingerprint (inherence).
  • Reduces the risk of unauthorized access even if one factor is compromised.

Memory trick: Know it, have it, be it: that's MFA's secret.

More Access Controls Concepts questions